5.4
CVSSv3

CVE-2017-2122

Published: 12/05/2017 Updated: 19/05/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting vulnerability in Nessus versions 6.8.0, 6.8.1, 6.9.0, 6.9.1 and 6.9.2 allows remote authenticated malicious users to inject arbitrary web script or HTML via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

tenable nessus 6.8.0

tenable nessus 6.8.1

tenable nessus 6.9.0

tenable nessus 6.9.1

tenable nessus 6.9.2

Vendor Advisories

Tenable Nessus was found to be impacted by two authenticated stored cross-site scripting (XSS) issues The first was via a report from Asif Balasinor, covered a reflected XSS issue that was deemed to have no risk as it could only be triggered by the authenticated user While evaluating that report the director of the Nessus development team, Nicol ...